SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-66476

MEDIUM · CVSS 4.9 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

Easy Digital Downloads versions up to 3.6.9 are vulnerable to an arbitrary file deletion flaw that allows administrators to delete files without proper authorization. This could lead to the loss of critical data or disruption of service for affected installations. Organizations using this plugin should prioritize patching to mitigate potential data loss and maintain system integrity.

CVE
CVE-2026-66476
Severity
MEDIUM
CVSS
4.9
EPSS
0.32%

Original NVD Description

Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.